CVE-2014-1350: Apple iPhone OS
Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.
Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
Affected products
- Apple iPhone OS: up to and including 7.1.1; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …
Published 2014-07-01. Last modified 2026-06-17.